Description
IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site scripting vulnerability in the administrative console login page.
Published: 2026-07-30
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a reflected cross‑site scripting flaw (CWE‑79) in the login page of IBM Tivoli System Automation Application Manager and WebSphere Application Server. It allows an attacker to inject arbitrary client‑side scripts that execute in the context of administrators who access the console, potentially enabling session hijacking, credential theft, or other malicious actions that compromise confidentiality, integrity, and availability of the managed environment.

Affected Systems

IBM Tivoli System Automation Application Manager version 4.1 and IBM WebSphere Application Server versions 8.5 and 9.0 are affected. The specific security bulletins for these product releases provide the relevant patch details.

Risk and Exploitability

The attack vector requires a user to interact with the vulnerable login page, typically via a crafted URL or a malicious link. An attacker can lure a privileged user into executing the injected scripts, then hijack the session or steal credentials. The CVSS score of 9.3 indicates high severity, while the EPSS score of < 1 % and the lack of a KEV listing suggest that exploitation is unlikely at present but the vulnerability remains high risk and requires immediate action.

Generated by OpenCVE AI on August 2, 2026 at 05:19 UTC.

Remediation

Vendor Solution

Principal Product and Version(s)Affected Supporting Product and VersionAffected Supporting Product Security BulletinIBM Tivoli System Automation Application Manager 4.1WebSphere Application Server 8.5 Security Bulletin: IBM WebSphere Application Server is affected by multiple cross-site scripting vulnerabilities (CVE-2026-11594, CVE-2026-11707, CVE-2026-11383) https://www.ibm.com/support/pages/node/7277546 IBM Tivoli System Automation Application Manager 4.1WebSphere Application Server 9.0 Security Bulletin: IBM WebSphere Application Server is affected by multiple cross-site scripting vulnerabilities (CVE-2026-11594, CVE-2026-11707, CVE-2026-11383) https://www.ibm.com/support/pages/node/7277546


OpenCVE Recommended Actions

  • Install the IBM security fix released for Tivoli System Automation Application Manager 4.1 and WebSphere Application Server 8.5/9.0 as described in the official bulletins.
  • Limit access to the administrative console to trusted networks or users, or disable the console for non‑administrative roles.
  • Implement a robust content‑security‑policy header or a web‑application‑firewall rule that blocks the execution of injected scripts as an interim defense.

Generated by OpenCVE AI on August 2, 2026 at 05:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Ibm aix
Ibm i
Ibm websphere Application Server
Ibm z\/os
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:ibm:tivoli_system_automation_application_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:z\/os:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Ibm aix
Ibm i
Ibm websphere Application Server
Ibm z\/os
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Thu, 30 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Cross-site Scripting in IBM WebSphere Application Server shipped with Tivoli System Automation Application Manager Multiple vulnerabilities have been identified in IBM WebSphere Application Server shipped with Tivoli System Automation Application Manager

Thu, 30 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Description IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site scripting vulnerability in the administrative console login page.
Title Cross-site Scripting in IBM WebSphere Application Server shipped with Tivoli System Automation Application Manager
First Time appeared Ibm
Ibm tivoli System Automation Application Manager
Weaknesses CWE-79
CPEs cpe:2.3:a:ibm:tivoli_system_automation_application_manager:4.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:tivoli_system_automation_application_manager:4.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm tivoli System Automation Application Manager
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'}


Subscriptions

Ibm Aix I Tivoli System Automation Application Manager Websphere Application Server Z\/os
Linux Linux Kernel
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-30T18:10:59.992Z

Reserved: 2026-06-08T23:43:19.847Z

Link: CVE-2026-11707

cve-icon Vulnrichment

Updated: 2026-07-30T15:16:17.356Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T15:16:24.010

Modified: 2026-08-18T13:27:06.663

Link: CVE-2026-11707

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T05:30:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')